preprojects records
29 published records for vendor preprojects.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 18
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Records by year
Bar: total · dark part: CISA KEV.
Recurring classes
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')18
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')4
- CWE-264 Permissions, Privileges, and Access Controls3
- CWE-255 Credentials Management Errors2
- CWE-20 Improper Input Validation1
- CWE-287 Improper Authentication1
The weakness classes this vendor ships most often: where to look.
CWEAll records
29 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
31Monitor | CVE-2008-6231Proof of concept | Pre Classified Listing PHP allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and preprojects · pre classified listings · CWE-255 | High7.5 | — | 2.9% | Feb 20, 2009 |
31Monitor | CVE-2008-6232Proof of concept | Pre Shopping Mall allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) apreprojects · pre shopping mall · CWE-255 | High7.5 | — | 2.9% | Feb 20, 2009 |
31Monitor | CVE-2008-6716Proof of concept | homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows remote attackers to hpreprojects · pre ads portal · CWE-287 | High7.5 | — | 2.5% | Apr 13, 2009 |
31Monitor | CVE-2008-2917Proof of concept | SQL injection vulnerability in productsofcat.asp in E-SMART CART allows remote attackers to execute arbitrary SQL commands via the category_preprojects · e-smart cart · CWE-89 | High7.5 | — | 1.7% | Jun 30, 2008 |
30Monitor | CVE-2010-0954No exploit | SQL injection vulnerability in search_result.asp in Pre Projects Pre E-Learning Portal allows remote attackers to execute arbitrary SQL commpreprojects · pre e-learning portal · CWE-89 | High7.5 | — | 1.3% | Mar 10, 2010 |
30Monitor | CVE-2012-5334Proof of concept | SQL injection vulnerability in product_desc.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the pid preprojects · pre printing press · CWE-89 | High7.5 | — | 1.3% | Oct 8, 2012 |
30Monitor | CVE-2012-5333Proof of concept | SQL injection vulnerability in page.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the id parameterpreprojects · pre printing press · CWE-89 | High7.5 | — | 1.2% | Oct 8, 2012 |
30Monitor | CVE-2010-1370No exploit | SQL injection vulnerability in detailad.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via thepreprojects · pre classified listings asp · CWE-89 | High7.5 | — | 1.1% | Apr 13, 2010 |
30Monitor | CVE-2011-5139Proof of concept | SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitrary SQL commands via preprojects · business cards designer · CWE-89 | High7.5 | — | 1.1% | Aug 31, 2012 |
30Monitor | CVE-2008-2915Proof of concept | Multiple SQL injection vulnerabilities in jobseekers/JobSearch.php (aka the search module) in Pre Job Board allow remote attackers to executpreprojects · pre job board · CWE-89 | High7.5 | — | 1.0% | Jun 30, 2008 |
30Monitor | CVE-2008-6230Proof of concept | SQL injection vulnerability in Tour.php in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary SQL commands via thepreprojects · pre podcast portal · CWE-89 | High7.5 | — | 1.0% | Feb 20, 2009 |
30Monitor | CVE-2008-2914Proof of concept | SQL injection vulnerability in jobseekers/JobSearch3.php (aka the search module) in PHP JOBWEBSITE PRO allows remote attackers to execute arpreprojects · php jobwebsite pro · CWE-89 | High7.5 | — | 1.0% | Jun 30, 2008 |
30Monitor | CVE-2008-6887Proof of concept | SQL injection vulnerability in detailad.asp in Pre Classified Listings 1.0 allows remote attackers to execute arbitrary SQL commands via thepreprojects · pre classified listings · CWE-89 | High7.5 | — | 1.0% | Aug 3, 2009 |
30Monitor | CVE-2010-4776Proof of concept | SQL injection vulnerability in takefreestart.php in PreProjects Pre Online Tests Generator Pro allows remote attackers to execute arbitrary preprojects · pre online tests generator · CWE-89 | High7.5 | — | 1.0% | Mar 23, 2011 |
30Monitor | CVE-2008-6796Proof of concept | SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to execute arbitrary SQL cpreprojects · pre real estate listings · CWE-89 | High7.5 | — | 1.0% | May 7, 2009 |
30Monitor | CVE-2010-1369Proof of concept | SQL injection vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the epreprojects · pre classified listings asp · CWE-89 | High7.5 | — | 1.0% | Apr 13, 2010 |
30Monitor | CVE-2008-2114Proof of concept | SQL injection vulnerability in emall/search.php in Pre Shopping Mall 1.1 allows remote attackers to execute arbitrary SQL commands via the spreprojects · pre shopping mall · CWE-89 | High7.5 | — | 1.0% | May 8, 2008 |
30Monitor | CVE-2008-4177Proof of concept | SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the c papreprojects · pre real estate listings · CWE-89 | High7.5 | — | 1.0% | Sep 23, 2008 |
30Monitor | CVE-2008-5977Proof of concept | SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the preprojects · php jobwebsite pro · CWE-89 | High7.5 | — | 1.0% | Jan 26, 2009 |
30Monitor | CVE-2008-6798Proof of concept | Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQLpreprojects · pre real estate listings · CWE-89 | High7.5 | — | 1.0% | May 7, 2009 |
27Monitor | CVE-2008-7052Proof of concept | Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticated users to execute preprojects · pre real estate listings · CWE-20 | Medium6.5 | — | 3.3% | Aug 24, 2009 |
27Monitor | CVE-2008-2916Proof of concept | Multiple SQL injection vulnerabilities in Pre ADS Portal 2.0 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execupreprojects · pre ads portal · CWE-89 | Medium6.8 | — | 1.1% | Jun 30, 2008 |
20Monitor | CVE-2008-6053No exploit | PreProjects Pre Resume Submitter stores onlineresume.mdb under the web root with insufficient access control, which allows remote attackers preprojects · pre resume submitter · CWE-264 | Medium5.0 | — | 1.3% | Feb 4, 2009 |
20Monitor | CVE-2008-6052No exploit | PreProjects Pre E-Learning Portal stores db_elearning.mdb under the web root with insufficient access control, which allows remote attackerspreprojects · pre e-learning portal · CWE-264 | Medium5.0 | — | 1.3% | Feb 4, 2009 |
20Monitor | CVE-2008-6055No exploit | PreProjects Pre Classified Listings stores pclasp.mdb under the web root with insufficient access control, which allows remote attackers to preprojects · pre classified listings · CWE-264 | Medium5.0 | — | 1.1% | Feb 4, 2009 |
- CVE-2008-623131Monitor
Pre Classified Listing PHP allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and
HighCVSS 7.5Proof of conceptEPSS 3%preprojects · pre classified listingsFeb 20, 2009
- CVE-2008-623231Monitor
Pre Shopping Mall allows remote attackers to bypass authentication and gain administrative access by setting the (1) adminname and the (2) a
HighCVSS 7.5Proof of conceptEPSS 3%preprojects · pre shopping mallFeb 20, 2009
- CVE-2008-671631Monitor
homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows remote attackers to h
HighCVSS 7.5Proof of conceptEPSS 2%preprojects · pre ads portalApr 13, 2009
- CVE-2008-291731Monitor
SQL injection vulnerability in productsofcat.asp in E-SMART CART allows remote attackers to execute arbitrary SQL commands via the category_
HighCVSS 7.5Proof of conceptEPSS 2%preprojects · e-smart cartJun 30, 2008
- CVE-2010-095430Monitor
SQL injection vulnerability in search_result.asp in Pre Projects Pre E-Learning Portal allows remote attackers to execute arbitrary SQL comm
HighCVSS 7.5No exploitEPSS 1%preprojects · pre e-learning portalMar 10, 2010
- CVE-2012-533430Monitor
SQL injection vulnerability in product_desc.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the pid
HighCVSS 7.5Proof of conceptEPSS 1%preprojects · pre printing pressOct 8, 2012
- CVE-2012-533330Monitor
SQL injection vulnerability in page.php in Pre Printing Press allows remote attackers to execute arbitrary SQL commands via the id parameter
HighCVSS 7.5Proof of conceptEPSS 1%preprojects · pre printing pressOct 8, 2012
- CVE-2010-137030Monitor
SQL injection vulnerability in detailad.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the
HighCVSS 7.5No exploitEPSS 1%preprojects · pre classified listings aspApr 13, 2010
- CVE-2011-513930Monitor
SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitrary SQL commands via
HighCVSS 7.5Proof of conceptEPSS 1%preprojects · business cards designerAug 31, 2012
- CVE-2008-291530Monitor
Multiple SQL injection vulnerabilities in jobseekers/JobSearch.php (aka the search module) in Pre Job Board allow remote attackers to execut
HighCVSS 7.5Proof of conceptEPSS 1%preprojects · pre job boardJun 30, 2008
- CVE-2008-623030Monitor
SQL injection vulnerability in Tour.php in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary SQL commands via the
HighCVSS 7.5Proof of conceptEPSS 1%preprojects · pre podcast portalFeb 20, 2009
- CVE-2008-291430Monitor
SQL injection vulnerability in jobseekers/JobSearch3.php (aka the search module) in PHP JOBWEBSITE PRO allows remote attackers to execute ar
HighCVSS 7.5Proof of conceptEPSS 1%preprojects · php jobwebsite proJun 30, 2008
- CVE-2008-688730Monitor
SQL injection vulnerability in detailad.asp in Pre Classified Listings 1.0 allows remote attackers to execute arbitrary SQL commands via the
HighCVSS 7.5Proof of conceptEPSS 1%preprojects · pre classified listingsAug 3, 2009
- CVE-2010-477630Monitor
SQL injection vulnerability in takefreestart.php in PreProjects Pre Online Tests Generator Pro allows remote attackers to execute arbitrary
HighCVSS 7.5Proof of conceptEPSS 1%preprojects · pre online tests generatorMar 23, 2011
- CVE-2008-679630Monitor
SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to execute arbitrary SQL c
HighCVSS 7.5Proof of conceptEPSS 1%preprojects · pre real estate listingsMay 7, 2009
- CVE-2010-136930Monitor
SQL injection vulnerability in signup.asp in Pre Classified Listings ASP allows remote attackers to execute arbitrary SQL commands via the e
HighCVSS 7.5Proof of conceptEPSS 1%preprojects · pre classified listings aspApr 13, 2010
- CVE-2008-211430Monitor
SQL injection vulnerability in emall/search.php in Pre Shopping Mall 1.1 allows remote attackers to execute arbitrary SQL commands via the s
HighCVSS 7.5Proof of conceptEPSS 1%preprojects · pre shopping mallMay 8, 2008
- CVE-2008-417730Monitor
SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL commands via the c pa
HighCVSS 7.5Proof of conceptEPSS 1%preprojects · pre real estate listingsSep 23, 2008
- CVE-2008-597730Monitor
SQL injection vulnerability in siteadmin/forgot.php in PHP JOBWEBSITE PRO allows remote attackers to execute arbitrary SQL commands via the
HighCVSS 7.5Proof of conceptEPSS 1%preprojects · php jobwebsite proJan 26, 2009
- CVE-2008-679830Monitor
Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to execute arbitrary SQL
HighCVSS 7.5Proof of conceptEPSS 1%preprojects · pre real estate listingsMay 7, 2009
- CVE-2008-705227Monitor
Unrestricted file upload vulnerability in profile.php in Pre Projects Pre Real Estate Listings allows remote authenticated users to execute
MediumCVSS 6.5Proof of conceptEPSS 3%preprojects · pre real estate listingsAug 24, 2009
- CVE-2008-291627Monitor
Multiple SQL injection vulnerabilities in Pre ADS Portal 2.0 and earlier, when magic_quotes_gpc is disabled, allow remote attackers to execu
MediumCVSS 6.8Proof of conceptEPSS 1%preprojects · pre ads portalJun 30, 2008
- CVE-2008-605320Monitor
PreProjects Pre Resume Submitter stores onlineresume.mdb under the web root with insufficient access control, which allows remote attackers
MediumCVSS 5.0No exploitEPSS 1%preprojects · pre resume submitterFeb 4, 2009
- CVE-2008-605220Monitor
PreProjects Pre E-Learning Portal stores db_elearning.mdb under the web root with insufficient access control, which allows remote attackers
MediumCVSS 5.0No exploitEPSS 1%preprojects · pre e-learning portalFeb 4, 2009
- CVE-2008-605520Monitor
PreProjects Pre Classified Listings stores pclasp.mdb under the web root with insufficient access control, which allows remote attackers to
MediumCVSS 5.0No exploitEPSS 1%preprojects · pre classified listingsFeb 4, 2009